GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

Security/Hacker

News linked to this event type.

Liquid Network resumes block production after a $320 million exploit

Liquid Network resumed empty block production after deploying an emergency patch, following a core software vulnerability that resulted in nearly $320 million in assets being withdrawn. Asset recovery and system stability monitoring are currently ongoing.

Research teams including the Ethereum Foundation use AI to optimize algorithms, reducing the resource threshold for quantum cracking of BTC and ETH by 50%

Odaily News: Researchers from institutions including the Ethereum Foundation, Theta Labs, and StarkWare have jointly published a paper, using AI coding agents to deeply optimize the core operations of Shor's algorithm. The computing resources required for a potential quantum attack on Bitcoin and Ethereum (secp256k1 cryptographic system) have been reduced by more than 50% compared to Google's benchmark in March of this year. The number of logical qubits required for the circuit has been compressed to 1,151, and later versions have even been reduced to 813. Although current quantum hardware still cannot directly break public chains, the research shows that pure algorithmic optimization is significantly narrowing the time window for the quantum threat. The researchers emphasize that quantum-resistant upgrades take a long time and cannot be applied retroactively, and the industry needs to prepare defenses in advance. (Coindesk)

$50 Million in Liquid Assets Must Be Fully Returned, Samson Mow Warns Alleged White Hat Hacker Attacker Leaves More Clues

according to Bitcoin News monitoring, Samson Mow has warned the alleged white hat hacker behind the Liquid attack that they may have left behind more clues than they realize. Mow stated, "The net of justice is wide and inescapable; no one will be spared." Mow also questioned the attacker's demand to return Bitcoin in exchange for a bounty, asking whether it is wise to publicly admit to taking Bitcoin and demand a bounty in return. Mow pointed out that Liquid's approximately $5 billion in assets, including L-BTC, Tether, and real-world assets, all belong to their respective issuers and holders, and cannot be used as a basis for calculating a bounty. Regardless of how other matters are negotiated, all user assets must be fully returned.

Osmosis Proposes Seizing Attacker Assets and Using Community BTC to Cover Alloyed BTC Collateral Shortfall

according to the Osmosis team, a solution proposal addressing the previous Nomic chain nBTC incident has now been published and has officially entered community discussion. Under the proposal, the Osmosis governance community will consider seizing the previously frozen attacker assets and using BTC accumulated in the community pool to cover the remaining collateral shortfall, in order to restore full collateral backing for Alloyed BTC. The plan still requires governance discussion and voting, and asset seizure or collateral replenishment has not yet been completed.

Binance Alpha 2.0 will support Nesa (NES) contract replacement, with trading resuming at 16:00 today.

Binance Wallet announced that following a security incident involving the Nesa (NES) token contract, Binance Alpha 2.0 will support NES contract swaps on BNB Smart Chain (BEP20) and provide compensation arrangements for eligible users: first, balances held by users as of 14:51 UTC on August 24, 2026, and maintained through to 04:00 UTC on September 5, 2026, will be swapped to the new contract at a 1:1 ratio; subsequent purchases will not be eligible for the swap and will be refunded separately. Second, users with net purchases of NES between 14:51 UTC on August 24, 2026, and 04:00 UTC on September 5, 2026, will receive an email detailing the specific refund plan within seven working days. Trading of NES on Binance Alpha 2.0 is expected to resume on September 10, 2026, at 08:00 UTC.

OpenAI appoints AI safety researcher Paul Christiano to the board of directors.

According to TechCrunch, AI alignment researcher Paul Christiano has officially joined the board of directors of the OpenAI Foundation and will serve as a member of its Safety and Security Committee. Christiano stated that he believes the rapid acceleration of AI capabilities poses a significant risk of "catastrophic and irreversible loss of control," and that the AI industry, including OpenAI, is not currently on track to effectively mitigate this risk. His appointment comes against the backdrop of several recent security incidents at OpenAI involving AI agents breaching constraints and infiltrating external computer systems, prompting widespread scrutiny of its safety protocols. Christiano is one of the core developers of the reinforcement learning (RLHF) technology. After leaving OpenAI in 2021 to found the Alignment Research Center (ARC), he will also continue to serve as an AI safety advisor to the U.S. government, though he will recuse himself from OpenAI-related matters and model evaluation work.

Over 50 BTC Rescued from COLDCARD Entropy Vulnerability Wallets, Funds Transferred to Crypto Recovery Trust Pending Return

Odaily News: According to Bitcoin News monitoring, DART stated that it and independent white-hat researchers have recovered over 50 BTC from wallets affected by the COLDCARD entropy vulnerability, completing the transfer before malicious attackers could steal the funds. DART is a digital asset recovery organization that works with white-hat researchers to protect vulnerable funds and coordinate their lawful return to owners. The white-hat researchers did not request a bounty and will return the Bitcoin to its owners.The rescued BTC has been transferred to the Crypto Recovery Trust. This trust is a dedicated statutory trust established under Wyoming state law to hold recovered digital assets and return them after confirming and verifying the legitimate owners. The trust will document the recovery process, separate the BTC from DART and researchers' funds, conduct blockchain analysis, ownership verification, and sanctions screening, and provide a lawful return process for verified owners. If ownership is disputed, or if the relevant funds involve sanctions or criminal proceedings, the BTC will be handled in accordance with applicable legal procedures. DART stated that other vulnerable assets and recovery leads are still under review.

Trezor Third-Party Email Service Provider Compromised, Phishing Emails Impersonate Official Communications

The official X account of Trezor (@Trezor) announced that its third-party email service provider was compromised by hackers, with a phishing email titled "Critical Security Alert: STM32 Entropy Vulnerability" circulating. Trezor explicitly clarified that the message was not sent by the company, and has urgently taken down the associated domains while launching an investigation. In recent days, Trezor had already suffered a customer data breach, resulting in the theft of the names, home addresses, and email addresses of approximately 67,000 users. Trezor advised users to avoid clicking any suspicious links and strictly refrain from disclosing their wallet mnemonics to anyone.

Ledger Appoints New Head of Security to Combat AI-Driven Crypto Attack Threats

According to Bloomberg, crypto hardware wallet manufacturer Ledger SAS has announced the hiring of Oded Blatman as Chief Information Officer (CIO) and Chief Security Officer (CSO), consolidating internal technology systems and security functions under a single executive lead. Previously with blockchain company Fireblocks, Blatman will oversee network and infrastructure security, product security, physical and workplace safety, internal IT, and enterprise risk management.

Liquid Network Releases Emergency Fix: Elements v23.3.4 Patches Proof Validation Cache Vulnerability

Odaily News: Liquid Network announced that the emergency release Elements v23.3.4 is now live, with Functionary nodes having immediately begun upgrades. All Liquid node operators are advised to update accordingly. This release addresses a previously identified Proof validation cache vulnerability by strengthening the cache keys used for Range Proofs.Regarding network recovery, Blockstream stated that a recovery plan is still being formulated, expected to proceed in three phases: **resume block production while continuing to pause Peg operations; replay verified valid transactions; restore Peg operations after the network state is fully recovered and fund returns are confirmed.** Currently, the first two phases are being tested in parallel, and any phase will only advance once confirmed secure.Liquid Network stated that Elements v23.3.4 has undergone multiple rounds of internal and external reviews, with participants including the Bitcoin Red Team, Alpen Labs, and other teams. Meanwhile, Liquid Network reminds users to be wary of fake upgrade websites exploiting this incident for scams. Information should only be obtained through official Liquid Network and Blockstream channels, and users should never send funds to strangers or disclose private keys or seed phrases.

Liquid white hat hacker group demands Blockstream pay 10% bug bounty for $5 billion in assets

According to Odaily Planet Daily, as monitored by Bitcoin News, the white hat hacker group behind the Liquid exploit has accused Blockstream of spending only $1.5 million—or possibly nothing at all—to secure $5 billion in assets. In a new on-chain message, the group demanded that Blockstream allocate its own funds to pay a bug bounty equivalent to 10% of the associated assets, warning that refusal to pay would result in a 15% loss for holders. The group also stated it would release the private keys used to decrypt previous communications with Blockstream. Earlier, the group had returned 3,400 BTC to the Liquid Federation, with approximately 600 BTC still unrepaid.

UK NCA warns criminals are "innovatively" using crypto assets to launder money

According to Decrypt, the UK National Economic Crime Centre (NECC) stated in its annual report that criminals are "innovatively" leveraging crypto asset products to evade detection and transfer illicit funds at scale, while also highlighting AI alongside cryptocurrencies as an emerging threat method. Crypto assets have been ranked third among the nine priority economic crime areas jointly designated by NECC, the FCA, and the Treasury. NECC stated it will build more proactive, intelligence-driven crypto capabilities to actively identify targets for enforcement action. Previously, the NCA, in collaboration with the US Secret Service, Coinbase, Binance, Kraken, and Tether, conducted "Operation Atlantic," which identified 20,000 phishing attack victims and resulted in the freezing of $12 million in assets this March.

738,600 USDC Transferred Out, Hyperliquid User Account Compromised with Over 10,000 HYPE Unstaked

Odaily News – A Hyperliquid user's account was compromised through unauthorized access, with approximately 738,600 USDC transferred out and an additional 10,287 HYPE unstaked. The affected account is identified by a specific address, with some of the stolen funds flowing to an address suspected to be associated with Bitget. As of the time of verification, the 10,287 HYPE remained in the staking balance and had not yet entered the withdrawal queue. If the attacker proceeds to initiate cWithdraw, the affected assets would be further transferred after a 7-day waiting period. In two similar recent cases, staked assets were stolen a second time due to the lack of a user-triggerable emergency pause mechanism, resulting in losses exceeding $1.1 million. Relevant recommendations include introducing a Guardian or Recovery mechanism that users can pre-enable, which would only temporarily pause withdrawals, transfers, and authorization changes. The pause would expire automatically, and restoration would require a time lock and evidence review, with all actions recorded on-chain.

Alby Hub old versions have critical vulnerability, publicly exposed management API could lead to fund transfer

Bitcoin News posted on X platform that Alby has confirmed a critical vulnerability in Alby Hub v1.7.0 through v1.18.5. If the management API is exposed to the public internet, attackers could gain unauthorized access and transfer funds. Currently, 1 user is known to be affected, and Alby Hub v1.19.0 and later versions are not affected. Alby recommends affected users restrict public access to the management interface, update to v1.24.0 immediately, and change their unlock password after updating. Multiple issues reported by Bitcoin Team Red, Project Loupe, and other researchers have also been fixed in the latest version.

ZachXBT Accuses Austin Fine of Allegedly Facilitating Money Laundering of Stolen Crypto Assets

On-chain detective ZachXBT posted allegations accusing user "Mr Austin Fine" (handle "@xmrfine") of helping Malone Lam, the mastermind behind a $245 million crypto fraud case, exchange funds for luxury goods and launder a portion of the stolen cryptocurrency, while also raising suspicions that he acted as an informant. ZachXBT has already traced on-chain, revealing that a portion of the funds flowed through Monero to Los Angeles luxury car dealer TBTFW for vehicle purchases.

Singaporean man pleads guilty to orchestrating $245 million cryptocurrency theft and money laundering crimes.

The U.S. Department of Justice stated that 22-year-old Singaporean national Marlon Ram pleaded guilty in federal court in Washington, D.C., admitting to participation in a conspiracy under the Racketeer Influenced and Corrupt Organizations Act. Prosecutors said the criminal network began operating around October 2023, obtained victims' information through social engineering and individual burglaries, and stole and laundered over $245 million in cryptocurrency.

Liquid Network: In discussions with white hat to recover remaining 598.5 BTC, network restoration efforts also underway

Liquid Network's official security incident report: On September 6, a vulnerability related to the range proof verification method in Liquid node caching within the open-source software Elements was exploited, resulting in the creation of approximately 4,000 LBTC tokens not backed by bitcoin reserves. The exploiter subsequently exchanged them for approximately 4,000 BTC via SideSwap and the Liquid standard Peg-out mechanism. Prior to the incident, Liquid's reserves stood at approximately 4,205 BTC. After the relevant Peg-out and other withdrawals completed before the network halt, reserves fell to 197 BTC.According to the official statement, the incident did not involve the compromise of Functionary nodes or private keys, and other issued assets on Liquid such as USDT were also unaffected by the vulnerability. The exploiter claimed to be a white hat security researcher and returned 3,400 BTC to the Liquid Federation Peg wallet on September 7. Approximately 598.5 BTC (about 15% of the funds involved) remain unrecovered, and Blockstream is in communication to recover the remaining assets.At present, the top priority is to recover the remaining funds and restore Liquid Network to normal operation as quickly and safely as possible. A fix for the vulnerability has been developed and is currently undergoing multiple rounds of internal and external review. Blockstream is preparing to urgently release Elements v23.3.4, which is expected to be rolled out as soon as preparations are complete, with a target launch within approximately 48 hours. Following the software update, Liquid Network Functionary operators will make further adjustments to restore full network functionality and resume a corrected network state, including rejecting previously invalid Peg-outs.

Coldcard thief prioritizes emptying third wave of vaults, has moved 97.09 BTC worth approximately $7.7 million

according to Bitcoin News monitoring, the Coldcard thief is prioritizing emptying the largest portion of the third wave of vaults. Galaxy Research stated that these wallets have transferred out 97.09 BTC, worth approximately $7.7 million, accounting for about 45% of the assets in this batch. The attacker created 293 2/2 vaults themselves and previously moved some tokens via THORChain on September 2, followed by multiple rounds of CoinJoin over the weekend. The vulnerability stems from a 2021 firmware flaw that reduced seed entropy to a minimum of 40 bits. Of the tokens stolen in this exploit, approximately 82% remain unmoved.

Four people killed in Mexico, suspects accused of stealing a cold wallet holding millions of dollars in Bitcoin

Odaily News: The State Attorney General's Office of Mexico (FGJEM) stated that two suspects are accused of killing four people in search of a cold wallet believed to contain millions of dollars in Bitcoin. The two are scheduled to appear in court on Wednesday, where a judge will determine whether there is sufficient evidence to continue criminal proceedings.The surnames of suspects Diego Sebastián and Gerardo have not been disclosed. Prosecutors allege that the pair killed Jonathan Meléndez, keyboardist for the rock band Camilo Séptimo, his pregnant wife, their daughter, and an employee at a residence in the city of Atizapán de Zaragoza. The family's golden retriever was also killed.Mexico's Secretary of Security, Omar García Harfuch, stated that one of the suspects was a business partner of the victim and allegedly used that relationship to gain entry into the residence. If convicted, the two could face sentences ranging from 25 to 70 years in prison for each victim.Blockchain security firm CertiK reported that 52 violent coercion attacks against cryptocurrency holders were recorded globally in the first half of 2026, a 33.3% increase from 39 during the same period in 2025. Blockchain analysis company Chainalysis estimates that the value of stolen cryptocurrency from related attacks exceeded $30 million. (Cointelegraph)

The Sandbox Launches SAND Compensation Claims

The Sandbox stated that it will provide full compensation to affected users for the SAND vulnerability incident on Base and BNB Smart Chain that occurred on August 22. Any wallet that legitimately held cross-chain SAND at the time of the snapshot prior to the incident will receive SAND compensation on the Ethereum network at a 1:1 ratio.